-
-
Notifications
You must be signed in to change notification settings - Fork 0
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
searching by status is fixed. ToolID is next up #178
Conversation
Here's the code health analysis summary for commits Analysis Summary
|
const { | ||
serialNumber, | ||
modelNumber, | ||
barcode, | ||
description, | ||
toolID, | ||
serviceAssignment, | ||
category, | ||
manufacturer, | ||
width, | ||
height, | ||
length, | ||
weight | ||
}, | ||
updatedBy: req.user._id, | ||
createdBy: req.user._id | ||
}) | ||
if (!newTool) { | ||
throw new Error({ message: 'Could not create tool', status: 500 }) | ||
} | ||
await ToolHistory.create({ | ||
_id: newTool._id, | ||
history: [newTool] | ||
}) | ||
res.locals.message = 'Successfully Made A New Tool' | ||
res.locals.tools = [newTool] | ||
res.locals.pagination = { pageCount: 1 } | ||
res.status(201) | ||
console.info(`[MW] Tool Successfully Created ${newTool._id}`.green) | ||
console.info('[MW] createTool-out-3'.bgWhite.blue) | ||
next() | ||
} catch (error) { | ||
res.locals.message = error.message | ||
res.status(error.status || 500).redirect('back') | ||
} | ||
} | ||
|
||
async function updateToolHistory(toolID) { | ||
const oldTool = await Tool.findById(toolID) | ||
await ToolHistory.findByIdAndUpdate( | ||
{ _id: toolID }, | ||
{ | ||
$push: { history: oldTool }, | ||
$inc: { __v: 1 }, | ||
$set: { updatedAt: Date.now() } | ||
} | ||
) | ||
} | ||
|
||
/** | ||
* | ||
* @param {*} req.body._id The id of the tool to update | ||
* @param {*} res | ||
* @param {*} next | ||
*/ | ||
async function updateTool(req, res, next) { | ||
console.info('[MW] updateTool-in'.bgBlue.white) | ||
const ut = async (newToolData) => { | ||
const { | ||
id, | ||
modelNumber, | ||
description, | ||
toolID, | ||
serviceAssignment, | ||
category, | ||
manufacturer, | ||
width, | ||
height, | ||
length, | ||
weight | ||
} = newToolData | ||
updateToolHistory(id) | ||
const updatedTool = await Tool.findByIdAndUpdate( | ||
{ $eq: id }, | ||
{ | ||
} = req.body |
Check failure
Code scanning / CodeQL
Type confusion through parameter tampering Critical
this HTTP request parameter
const { | ||
id, | ||
modelNumber, | ||
description, | ||
toolID, | ||
serviceAssignment, | ||
category, | ||
manufacturer, | ||
width, | ||
height, | ||
length, | ||
weight | ||
} = newToolData |
Check failure
Code scanning / CodeQL
Type confusion through parameter tampering Critical
this HTTP request parameter
} | ||
|
||
async function updateToolHistory(toolID) { | ||
const oldTool = await Tool.findById(toolID) |
Check failure
Code scanning / CodeQL
Database query built from user-controlled sources High
user-provided value
This query object depends on a
user-provided value
async function updateToolHistory(toolID) { | ||
const oldTool = await Tool.findById(toolID) | ||
await ToolHistory.findByIdAndUpdate( | ||
{ _id: toolID }, |
Check failure
Code scanning / CodeQL
Database query built from user-controlled sources High
user-provided value
This query object depends on a
user-provided value
} = newToolData | ||
updateToolHistory(id) | ||
const updatedTool = await Tool.findByIdAndUpdate( | ||
{ $eq: id }, |
Check failure
Code scanning / CodeQL
Database query built from user-controlled sources High
user-provided value
updateToolHistory(id[i]) | ||
newTools.push( | ||
await Tool.findByIdAndUpdate( | ||
{ _id: id[i] }, |
Check failure
Code scanning / CodeQL
Database query built from user-controlled sources High
user-provided value
{ | ||
serviceAssignment: newServiceAssignment[i], | ||
$inc: { __v: 1 }, | ||
$set: { updatedAt: Date.now() } | ||
}, |
Check failure
Code scanning / CodeQL
Database query built from user-controlled sources High
This change is